Acceptable Use Policy (AUP)
Effective Date: August 2026·Version 2.0
Standard of Conduct
This Acceptable Use Policy outlines the rules and standards required of all users of SiteMind. By creating a workspace, generating embeddings, or embedding our widgets, you agree to adhere strictly to these guidelines.
1. Prohibited Content
- Illegal Content: Any content that violates applicable local, national, or international laws, including child sexual abuse material (CSAM), human trafficking, or terrorism recruitment.
- Malicious Software: Distributing viruses, trojans, worms, ransomware, keyloggers, or other harmful computer code.
- Infringing Material: Indexing, uploading, or distributing text, documents, or media that infringe copyright, trademark, patent, trade secret, or other intellectual property rights of third parties.
- Harassment & Defamation: Using the assistant or widget to generate defamatory, threatening, abusive, racially offensive, or hateful communications.
- Phishing & Deceptive Impersonation: Forging identities, deploying deceitful lead-capture forms, or pretending to be an unaffiliated financial, governmental, or law enforcement institution.
2. Regulated Data Prohibitions (HIPAA, PCI & Financial Data)
- Protected Health Information (PHI): SiteMind is designed for public website assistance and general logistical support. SiteMind is NOT a HIPAA-compliant repository and does not execute Business Associate Agreements (BAAs). You MUST NOT upload, crawl, or solicit Protected Health Information (PHI), medical records, or diagnostic data through the Service.
- Payment Card Data (PCI-DSS): You MUST NOT use SiteMind chat forms or document uploads to collect or store primary account numbers (PANs), card security codes (CVV/CVC), or bank account PINs.
- Classified & National Security Data: Ingesting government-classified information, defense articles, or export-controlled technological data is strictly forbidden.
3. Prohibited Technical Activities & Abuse
- Adversarial Prompt Injection & Jailbreaks: Attempting to bypass system safety guardrails, force model instruction leakage, or manipulate the assistant to execute unauthorized system commands.
- Unauthorized Crawling & Web Scraping: Initiating crawl jobs against domains you do not own or for which you lack explicit written authorization to scrape.
- Denial of Service & Rate-Limit Bypasses: Flooding API endpoints, deploying automated bot attacks, rotating forged headers to evade rate limiters, or interfering with system availability for other customers.
- Reverse Engineering: Decompiling, reverse-engineering, or extracting proprietary source code, vector ranking heuristics, or prompt templates from the SiteMind platform.
- Security Probing: Performing uncoordinated vulnerability scans, penetration testing, or stress tests against SiteMind production infrastructure without prior written authorization from [email protected].
4. Crawler Etiquette & Fair Use
- Authorized Scope: Crawlers must only be targeted at public website URLs and approved subdirectories.
- Traffic Limits: SiteMind enforces concurrency controls and domain-level crawl ceilings to ensure destination web servers are not overwhelmed.
- Resource Respect: If a target website owner requests the cessation of crawling, Customer must immediately disconnect the domain.
5. Enforcement, Investigation & Reporting
- Monitoring & Investigation: SiteMind reserves the right to investigate any suspected violation of this Policy, inspect anomalous traffic patterns, and cooperate with law enforcement authorities.
- Remediation Actions: In the event of a violation, SiteMind may issue warnings, remove offending content, disable crawler jobs, or immediately suspend or terminate workspace access without liability or refund.
- Abuse Reporting: To report suspected abuse, spam, phishing, or safety violations involving a SiteMind widget, contact us immediately at [email protected] or [email protected].
Related Legal Documents